
The thorny issue of cybersecurity. Are "real" casinos under threat?
Attacks on the biggest establishments - MGM Resorts and Caesars - have been one of the main topics of the past weeks. Losses run into the hundreds of millions of dollars. The companies' stocks have plummeted sharply downward. Most importantly, a huge array of players' personal data has likely been compromised, although the casinos deny the possibility. Therefore, the issue of cybersecurity has become extremely acute. Analysts investigate how things are going with user data protection and casino security.
What happened at MGM and Caesars
The hacker attack on MGM Resorts took place on September 11 this year. It all started when the casino reported security problems at the company. The message appeared on the social network X (formerly Twitter). MGM then tried to pretend as if everything was under control, assuring that all necessary measures to protect customer data had been taken.
However, this reassuring assertion proved to be somewhat premature. Hackers continued to attack the casino, causing the company's operations to be interrupted for several days. Hotel room keys, slot machines, and many other things in the infrastructure of the hotels and casinos were affected. Most of the impact came in Las Vegas.But the reverberations were felt around the world, as MGM is one of the largest companies offering offline casino services.
Most of the facilities had to be converted to "analog mode. “Staff recorded bets and winnings on paper. In just a few hours, the biggest and richest casino chain returned not even to the middle, but the beginning of the twentieth century.
In all, it took the company more than ten days to recover. Only on September 20, MGM reported that everything was working normally. However, to this day, some functions are still unavailable - mainly related to advertising and bonuses.
Less is known about the attack on Caesars. However, the company reported that it was also attacked by hackers, and it happened on September 7. Caesars does not go into details about what facilities were affected, or what damage the casino suffered. They also ensure that players' personal data is not affected. However, there have been repeated reports that Caesars actually paid off the hackers, giving more than 15 million dollars.
How the attack occurred
The exact details are not known. However, there is information that the Scattered Spider group, also known as UNC3944, is behind both attacks. The hackers used a special hacking software, BlackCat Ransomware as a Service (RaaS). However, in such cases, software alone is not enough.
Social engineering comes to the fore. There are various ways to manipulate and deceive to gain access to sensitive information. It is believed that in both cases, some third party was the culprit.
Caesars blames the IT support provider. In MGM's case, a "planted duck" entered the trust as an employee before gaining access to the passwords and data needed.
The hackers may also have used information found on the social network LinkedIn to pretend to be employees of the IT company.
Fishing: the main threat
Analysts have already drawn the main conclusion from the situation. The IT defense systems themselves are quite reliable. No hacker software can crack them without the "human factor". The latter is most often phishing. Many of us have encountered it when we were sent a dubious link to enter our card number. Or a call from a bank informing us about a loan allegedly taken out in our name - "Protect your money by forwarding it to such and such a contact".
Seemingly obvious techniques. But they work because today's cybercriminals rely less and less on software and more and more on social engineering.The methods are becoming more sophisticated. Cybercriminals use dipfakes to mimic the voice and face of trusted people - for example, the head of security or the IT department. This is what enables criminals to carry out their black designs.
Why offline casinos are at risk
In online establishments, everything is decentralized. There is no single head of security who can give away all access. Protection goes through several stages - even if one person in the chain gets caught phishing, another can turn on the mind in time and catch an insidious hacker by the hand.Therefore, the analysts conclude, that virtual casinos, as well as other decentralized institutions, are now more secure. They rely more often on AI, and it is harder to deceive a machine than a human.
In the future, analysts believe that offline establishments will also strive to minimize the human factor. This is the only way to protect themselves from hacker attacks.
3 November 2023, 17:13
Articles
Why will the Snaitech deal double Flutter's market share in Italy?
26 September 2024, 16:00
Hiring Talent from Different Industries: Why and How?
26 September 2024, 09:09
The Social Casino Phenomenon: Real Money and Databases for Bookmakers
20 September 2024, 17:18
Dividing the Peruvian Pie: Who Will Take Over the Market After the Regulatory Law?
20 September 2024, 14:10
Expert Opinion: Why Betting Can't Survive Without AI Analysis of Sports Data
13 September 2024, 11:00
Finnish Gambling Market Reform: Veikkaus Resurgent vs Kindred's Leadership
10 September 2024, 19:00
Other news
Gambling adverts during football matches triple in UK
29 September 2024, 16:17
Merkur Group founder to step down as chairman after 67 years at the helm
29 September 2024, 09:22
Dutch players demand bookmakers refund their money
28 September 2024, 15:14
Flutter Enters Top 3 Largest Bookmakers in Brazil
28 September 2024, 10:08
DraftKings to Pay $200,000 Fine Over Social Media Post
27 September 2024, 15:41
Star Entertainment Group Reports Financial Downturn
27 September 2024, 10:54
Norfolk casino project approved by Architectural Review Board
26 September 2024, 14:37
Flutter Entertainment aims to triple profits
26 September 2024, 09:19
Five social casino ads banned in UK
25 September 2024, 10:27
Brazil's WA.Technology Acquires Onseo
24 September 2024, 17:24
ESPN Bet Could Launch in New York by Weekend
24 September 2024, 08:30
EveryMatrix Appoints Former Entain Employee as Product Director
23 September 2024, 17:03
Articles
Why will the Snaitech deal double Flutter's market share in Italy?
26 September 2024, 16:00
Hiring Talent from Different Industries: Why and How?
26 September 2024, 09:09
The Social Casino Phenomenon: Real Money and Databases for Bookmakers
20 September 2024, 17:18
Dividing the Peruvian Pie: Who Will Take Over the Market After the Regulatory Law?
20 September 2024, 14:10
Expert Opinion: Why Betting Can't Survive Without AI Analysis of Sports Data
13 September 2024, 11:00